CVE-2021-21365

MEDIUM

Typo3 < 7.1.2 - XSS

Title source: rule
STIX 2.1

Description

Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. Users of the extension, who have overwritten the affected templates with custom code must manually apply the security fix. Update to version 7.1.2, 8.0.8, 9.1.4, 10.0.10 or 11.0.3 of the Bootstrap Package that fix the problem described. Updated version are available from the TYPO3 extension manager, Packagist and at https://extensions.typo3.org/extension/download/bootstrap_package/.

References (3)

Core 3

Scores

CVSS v3 5.4
EPSS 0.0034
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
bk2k/bootstrap-package 7.1.0 - 7.1.2Packagist
typo3/typo3 < 7.1.2
Published Apr 27, 2021
Tracked Since Feb 18, 2026